Connect with us

News

NCC-CSIRT identifies two cyber attacks via Facebook, charging phones

Published

on

Nasiru Yusuf

The Nigerian Communications Commission’s Cyber Security Incident Response Team (NCC-CSIRT) has independently identified two cyber vulnerabilities and advised Nigerian telecom consumers on the measures to be taken to get protected from the cyber-attacks.

KANO FOCUS reports that the CSIRT, in its first-ever security advisories less than three months after its creation, has solely identified the two cyber-attacks targeting the consumers and proffer solutions that can help telecom consumers from falling victims to the two cyber vulnerabilities.

This is contained in a statement sent to KANO FOCUS by Director, Public Affairs Dr. Ikechukwu Adinde on Friday.

The statement said the first is described as Juice Jacking, which can gain access into consumers’ devices when charging mobile phones at public charging stations and it applies to all mobile phones.

The other is a Facebook for Android Friend Acceptance Vulnerability, which targets only Android Operating System.

According to CSIRT security Advisory 0001 released on January 26, 2022, with Juice Jacking, attackers have found a new way to gain unauthorized entry into unsuspecting mobile phone users devices when they charge their mobile phones at public charging stations.

Many public spaces, restaurants, malls and even in the public trains do offer complementary services to their customers in a bid to enhance customer services, one of which is providing charging ports or sockets.

However, an attacker can leverage this courtesy to load a payload in the charging station or on the cables they would leave plugged in at the stations.

“Once unsuspecting persons plug their phones at the charging station or the cable left by the attacker, the payload is automatically downloaded on the victims’ phone.

“This payload then gives the attacker remote access to the mobile phone, allowing them to monitor data transmitted as text, or audio using the microphone. The attacker can even watch the victim in real time if the victims’ camera is not covered. The attacker is also given full access to the gallery and also to the phone’s Global Positioning System (GPS) location.

“When an attacker gains access to a user’s Mobile phone, he gets remote access to the User’s phone which leads to breach in Confidentiality, Violation of Data Integrity and bypass of Authentication Mechanisms. Symptoms of attack may include sudden spike in battery consumption, device operating slower than usual, apps taking a long time to load, and when they load they crash frequently and cause abnormal data usage,” the statement said.

It added that the NCC-CSIRT, however, proffered solutions to this attack to include using ‘charging only USB cable’, to avoid Universal Serial Bus (USB) data connection; using one’s AC charging adaptor in public space; and not granting trust to portable devices prompt for USB data connection.

Other preventive measures against Juice Jacking, according to the statement include installing Antivirus and updating them to the latest definitions always; keeping mobile devices up to date with the latest patches; using one’s own power bank; keeping mobile phone off when charging in public places; as well as ensuring use of one’s own charger, if one must charge in public.

On the other hand, the NCC-CSIRT Advisory 0001 of January 27, 2022, warns that Facebook for Android is vulnerable to a permission issue which gives privilege to anyone with physical access to the android device to accept friend requests without unlocking the phone. The products affected include Versions 329.0.0.29.120 of Android OS.

With this, the attacker will be able to add the victim as a friend and collect personal information of the victim, such as Email, Date of Birth, Check-ins, Mobile phone number, Address, Pictures and other information that the victim may have shared, which would only be visible to his/her friends.

However, to be protected from the Facebook-associated vulnerability, NCC-CSIRT in the security advisory recommends to users to disable the feature from their device’s lock screen notification settings.

The NCC-CSIRT was inaugurated in October, 2021 to provide guidance and direction for the constituents in dealing with issues relating to the security of critical infrastructure in their possession, and periodically assess, review and collate the threat landscape, risks, and opportunities affecting the communications sector, in order to provide advice to relevant stakeholders in those regards.

As the telecoms-industry specific intervention, the objective of which aligns with the objective of the National Cybersecurity Policy and Strategy (NCPS) document published by the Office of the National Security Adviser (ONSA), the NCC-CSIRT ensures continuous improvement of processes and communication frameworks to guarantee secure and collaborative exchange of timely information while responding to cyber threats within the sector.

In recent times, NCC-CSIRT has raised series of cyber-vulnerability awareness based on security advisories it receives from the Nigerian Cybersecurity Emergency Response Team (ngCERT), which is the national body for the implementation of the NCPS objective. However, Juice Jacking and Facebook for Android Friend Acceptance Vulnerabilities are the two first-ever cyber vulnerabilities published by the NCC-CSIRT.

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Headlines

Ganduje’s eldest son pays solidarity visit to Kano anti-corruption chairman, ‘lauds govt for investigating father

Published

on

Mukhtar Yahya Usman

Abdulazeez Ganduje, the eldest son of the suspended national chairman of the All Progressives Congress (APC), Abdullahi Ganduje, paid a visit to the chairman of the Kano State Public Complaints and Anti-Corruption Commission, Muhyi Rimingado, at his office.

Mr. Abdulazeez visited Mr. Rimingado on Wednesday evening to show his support for the chairman’s anti-corruption efforts.

He also expressed his endorsement of the charges brought against his father, mother, and brother by the commission.

Abdulazeez voiced his concern to the commission chairman about his unjust removal as a director of one of the companies undergoing trial, expressing his distress over being ousted without his consent.

In September 2021, Abdulazeez lodged a petition with the Economic and Financial Crimes Commission (EFCC) against his mother, Hafsat Ganduje, accusing her of corruption. In the petition, he detailed how he was approached by a property developer to assist in acquiring land in Kano for a substantial sum of money.

It was revealed that Abdulazeez paid the specified amounts in US dollars to his mother, Mrs. Ganduje. However, the property developer later discovered that the land he had paid for had been allocated to other buyers and requested a refund.

The Kano anti-corruption commission had previously taken legal action against Mr. Ganduje, his wife, Hafsat Umar, his son Umar Abdullahi Umar, and five others on charges related to corruption, misappropriation, and diversion of funds, amounting to billions of naira. Other individuals involved include Abubakar Bawuro, Jibrilla Muhammad, Lamash Properties Limited, Safari Textiles Limited, and Lasage General Limited.

Continue Reading

Headlines

Breaking: Kano High Court affirms Ganduje’s suspension

Published

on

Ganduje

Nasiru Yusuf Ibrahim

 

Kano state high Court has affirmed the suspension of the National Chairman of the All Progressive Congress, APC, Dr. Abdullahi Umar Ganduje as member of the party.

KANO FOCUS reports that the court presided over by Justice Usman Malam Na’abba on Tuesday affirmed the suspension following an exparte motion filed by Dr. Ibrahim Sa’ad Esq on behalf of two executive members APC Ganduje ward, Dawakin-Tofa local government area, the assistant secretary, Laminu Sani and legal adviser Haladu Gwanjo (plaintiffs) who were part of the nine ward executive who suspended Abdullahi Ganduje on Monday.

The order followed an ex parte motion filed Haladu Gwanjo and Laminu Sani by their counsel Ibrahim Sa’ad.

The plaintiffs, who identified as executive members of APC Ganduje ward, said they brought the motion on behalf of the executive members of the ward.

Gwanjo, who identified as the party’s ward Legal Adviser, was the one that announced the suspension of Ganduje two days ago.

Subsequently, the court ordered, that henceforth, Ganduje should desist from presiding over all affairs of the National Working Committee (NWC) of APC.

The State Working Committee of the All Progressive Congress (APC) in Kano had announced the suspension of ward party leaders who earlier announced the suspension of Ganduje.

Recall that the leadership of the party at Ganduje ward in Dawkin Tofa Local Government area announced the suspension of the party’s national chairman, citing corruption charges filed against him by the government.

Continue Reading

Headlines

Court asks Ganduje to stop parading himself as APC member, affirm suspension

Published

on

Mukhtar Yahya Usman

Kano state high Court has granted an exparte order restraining the National Chairman of All Progressives Congress (APC) Dr. Abdullahi Umar Ganduje from parading himself as member of the party.

KANO FOCUS reports that subsequently, the court ordered, that henceforth, Ganduje should desist from presiding over all affairs of the National Working Committee (NWC) of APC.

The application granted by Justice Usman Malam Na’abba on Tuesday follows an exparte motion filed by Dr. Ibrahim Sa’ad Esq on behalf of two executive members APC Ganduje ward, Dawakin-Tofa local government area, the assistant secretary, Laminu Sani and legal adviser Haladu Gwanjo (plaintiffs) who were part of the nine ward executive who suspended Abdullahi Ganduje two days ago.

The court directed the four parties (respondents) joined in the matter, include All Progressives Congress (APC), APC National Working Committee (NWC), APC Kano State Working Committee (KSWC), and Dr. Abdullahi Umar Ganduje, to henceforth, maintain status quo ante belum as from 15th April, 2024, pending the hearing and determination of the substantive suit on 30th April, 2024.

Justice Na’abba also held as prayed, stopped State Working Committee APC Kano, from interfering with the legally and validly considered decision of executives of Ganduje ward, essentially on action endorsed by two third majority of the executives as provided by the party constitution.

“An order is hereby granted directing all parties in the suit APC (1st), APC National Working Committee (2nd), Kano State Working Committee APC (3rd), Dr. Abdullah Umar Ganduje (4th), to maintain status quo ante belum as of 15th April, 2024.

” The order thereby restraining the 1st respondent (APC) from recognizing the 4th respondent (Ganduje) as member of APC and prohibiting the 4th respondent (Ganduje) from presiding over any affairs of the NWC and restraining the state Working Committee from interfering with the legally and validly decision of the ward executives of Ganduje ward.

“That the 4th respondent (Ganduje) is prohibited from parading himself as member of APC or doing any act that may portray him or seem to be a member of APC pending the hearing and determination of the substantive suit”.

It will be recalled that nine members of the Ganduje ward proclaimed the suspension of the National Chairman of APC over the allegation of corruption slammed on him by Kano state government.

The nine APC executives said they were prompted to act following a petition written by one Ja’afaru Adamu, a member of APC from the National Chairman’s polling unit.

In the petition, Adamu complained over allegation of corruption charges against the former Governor just as he urged the ward leaders to investigate the matter to redeem the dented image of the party and the implication on President Bola Tinubu’s fight against corruption.

Although, the chairman and secretary of the ward failed to act on the petition filed since 8th April, 2024, nine members of the executives led by the legal adviser had acted upon the petition, a decision that led to the suspension Dr. Abdullahi Umar Ganduje.

In the last one year, the former Kano state Governor Abdullahi Ganduje had suffered serious political setback for loosing his Dawakin Tofa federal constituency in the 2023 general elections where his son U
Sent from my iPhone

Continue Reading

Upcoming Events

There are no upcoming events at this time.

Facebook

Twitter

Trending